Skip to main content
Community Hub
TL;DR

Create an OAuth client in SAP Analytics Cloud so Atlan can crawl folders, stories, models, and columns using the client credentials grant.

Your AI can read this via Docs MCPcurl -fsSL "https://docs.atlan.com/install-docs-mcp" | bashConnect

Set up SAP Analytics Cloud Private Preview

Atlan connects to the SAP Analytics Cloud REST APIs with an OAuth 2.0 client that uses the client credentials grant. Create the OAuth client in your tenant and collect the details Atlan needs to crawl metadata.

Prerequisites​

Before you begin, make sure you have:

  • A user with the Admin role in your SAP Analytics Cloud tenant. Only administrators can create OAuth clients.
  • Access to the Data Export service in your tenant. If the Data Export Service option doesn't appear when you create the OAuth client, contact SAP support to enable the Data Export API for your tenant.

Create OAuth client​

  1. Sign in to SAP Analytics Cloud as an administrator.

  2. From the side navigation, click System > Administration, and then open the App Integration tab.

  3. Under Configured Clients, click Add a New OAuth Client.

  4. For Name, enter a name that identifies the client, for example Atlan.

  5. For Purpose, select API Access. On some tenants, this option is labeled Interactive Usage and API Access.

  6. Under Access, select the following options:

    • Story Listing: Lists stories and the models each story uses.
    • File Repository Read: Lists folders, stories, and models.
    • Data Import Service: Lists models and their metadata.
    • Data Export Service: Reads model columns.

    Atlan doesn't need the other access options, such as User Provisioning or Catalogue User API.

  7. For Authorization Grant, select Client Credentials.

  8. For Secret, set a Lifetime in days. When the secret expires, the crawler fails until an administrator resets the secret and you update the credentials in Atlan.

  9. Click Add.

Collect connection details​

Note the following values to enter when you crawl SAP Analytics Cloud:

  • Tenant URL: The base URL of your SAP Analytics Cloud tenant, as shown in your browser address bar, for example https://<tenant>.<data-center>.analytics.cloud.sap. Include only the protocol and host, not the path.
  • Token URL: On the App Integration tab, under OAuth Clients, copy the Token URL, for example https://<tenant>.authentication.<data-center>.hana.ondemand.com/oauth/token. Don't use the Authorization URL or the OAuth2SAML Token URL, which appear next to it.
  • Client ID and Client Secret: Under Configured Clients, click the edit icon of the OAuth client you created to view its client ID and secret.

The OAuth client can read all content in the tenant, including folders that belong to other users. To limit what Atlan catalogs, use the folder filters when you configure the crawler.

Next steps​